Skip to main content

Yacht Cybersecurity Alerts · Updated Hourly

Superyacht Cybersecurity Threat Intelligence

Live CVE alerts, CISA KEV vulnerabilities, NVD disclosures, and cyber news for yacht crews, ETOs, captains, managers, and onboard IT teams.

Updated 9 min ago

CISA KEV Watchlist for Yacht Cybersecurity

CISA Cybersecurity Risks for Yachts — Satcom & connectivity

Active cyber threats that can reach the yacht through crew devices, remote access, onboard networks, and connected systems.

No active CISA-KEV entries match Satcom & connectivity in the current snapshot. Clear filter →

See the full Satcom & connectivity catalog (0 entries) →

Filtered to Satcom & connectivity. Search, sort, and paginate the rest on the full catalog page.

Want crew who know what to do when one of these lands in their inbox? Start the free hour-long course →

Superyacht Cybersecurity Risks

New CVE Risks for Yacht IT

Recently disclosed CVEs ranked critical-first for yacht IT, AV, remote access, firewalls, routers, and onboard networks.

CVE CVSS Severity Published Description
CVE-2026-61539 10 CRITICAL Aug 21, 2026 Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model/llm/tool_parsers/llama3_tool_parser.py and xinference/model/llm/utils.py. Requests to /v1/chat/completions with a tools field flow through xinference/api/rest…
CVE-2026-69502 10 CRITICAL Aug 21, 2026 Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62283 9.9 CRITICAL Aug 21, 2026 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream identifiers created by CreateStream in service/rpc/io_stream.go to their creating user, and `GET /ws/terminal/:id` and `GET /ws/file/:id` only check whether the supplied UUID exists…
CVE-2026-77810 9.9 CRITICAL Aug 21, 2026 In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, users should upgrade to aws-athena-query-federation v2026.30.1 or later.
CVE-2026-63343 9.9 CRITICAL Aug 21, 2026 Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file on the host as root via the instance metadata API. The `exec-output` and `templates/` paths were patched in a prior release…
CVE-2026-63125 9.9 CRITICAL Aug 21, 2026 Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as root on the host. A crafted image ships `backup.yaml` as a symlink to a host file. When the root daemon writes the inst…
CVE-2026-62941 9.9 CRITICAL Aug 21, 2026 Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is merged into the request. Dangerous configuration keys (including `security.privileged`, `raw.lxc`, `raw.apparmor`) from the sourc…
CVE-2026-62940 9.9 CRITICAL Aug 21, 2026 Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including security-critical keys like `security.privileged` and `raw.lxc`) are applied without any project restriction enforcement, allowing a restricted project user to escalate to a p…
CVE-2026-62867 9.9 CRITICAL Aug 21, 2026 Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem creation command line. This allows a project-scoped user to inject arbitrary arguments into the binary executed as root. Version…
CVE-2026-48769 9.9 CRITICAL Aug 21, 2026 Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server. Version 7.2.0 patches the issue.
CVE-2026-48755 9.9 CRITICAL Aug 21, 2026 Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write on the host, possibly leading to arbitrary command execution. Version 7.1.0 patches the issue.
CVE-2026-48753 9.9 CRITICAL Aug 21, 2026 Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the issue.
CVE-2026-48752 9.9 CRITICAL Aug 21, 2026 Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 patches the issue.
CVE-2026-48751 9.9 CRITICAL Aug 21, 2026 Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel hooks such as `raw.lxc` and `raw.qemu`. Version 7.2.0 patches the issue.
CVE-2026-48750 9.9 CRITICAL Aug 21, 2026 Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `exec-output` is a symlink, file named `exec_UUID.stdout` and `exec_UUID.stderr` can be written to an arbitrary location whe…
CVE-2026-48749 9.9 CRITICAL Aug 21, 2026 Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 fixes the issue.
CVE-2026-76904 9.8 CRITICAL Aug 21, 2026 GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when executing OGC Filters with PostGIS DataStore implementation: `jsonArrayContains` function; Requires PostGIS 12 or greater with a String or JSON field. For PostGIS…
CVE-2026-74581 9.8 CRITICAL Aug 21, 2026 In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(), but leaves res->rt6 pointing at the released rt6_info. If no later rule supplies a replacement, fib6_rule_lookup() still sees res.rt6 and returns that stale dst to its caller.…
CVE-2026-77806 9.8 CRITICAL Aug 21, 2026 SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.
CVE-2026-77087 9.6 CRITICAL Aug 21, 2026 Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip locally, uses DNS rebinding to make authenticated API requests and execute commands through the process adapter.
CVE-2026-49849 9.1 CRITICAL Aug 21, 2026 xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administrator to upload executable files (e.g., .php). By uploading a specially crafted php file, an attacker can achieve Remote Code Execution (RCE) on the server, leading to a full system compromise. Version 3.0.4 fix…
CVE-2026-62674 9 CRITICAL Aug 21, 2026 Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but does not reject a bound shared or template agent whose agent.session_id is None. An authenticated user with edit access to a session can replace that shared agent bund…
CVE-2026-19883 8.8 HIGH Aug 22, 2026 The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the wpematico_import_settings function in all versions up to, and including, 2.8.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to u…
CVE-2026-53528 8.8 HIGH Aug 21, 2026 LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset rename functionality. An authenticated user with editor permissions could move files that are accessible to the LeafWiki server process into a page’s asset directory. This could allow sensitive local files, such as the application database,…
CVE-2026-53527 8.8 HIGH Aug 21, 2026 LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerability in the user update API. An authenticated user could update their own account role and escalate privileges from a regular user, such as `viewer`, to `admin`. Exploitation requires a valid authenticated LeafWiki user account. Instances without public regist…

Phishing emails carry these payloads. Train crew to spot the trigger →

From the Cybersecurity Newsroom

What's making cyber headlines

Hand-picked feeds from Krebs on Security, The Hacker News, BleepingComputer, and SANS ISC.

BleepingComputer
Malicious npm packages evade install-script defenses at runtime
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. [...]
Sep 20, 2026
Read at source →
BleepingComputer
Researchers escape OpenAI Codex sandbox to run commands on host
Researchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both. [...]
Sep 20, 2026
Read at source →
The Hacker News
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that runs OpenAI'…
Sep 19, 2026
Read at source →
BleepingComputer
BragJack attacks hijack AI browser agents through malicious extensions
BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension. The Prompt Forcing technique earned over $20,000 in bounties and two CVEs. [...]
Sep 19, 2026
Read at source →
BleepingComputer
North Korean WaterPlum hackers infected 30,000 devices worldwide
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. [...]
Sep 19, 2026
Read at source →
BleepingComputer
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. [...]
Sep 19, 2026
Read at source →
The Hacker News
Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is compressing the time between disclosure and working exploitation, while many secu…
Sep 19, 2026
Read at source →
The Hacker News
Identity Visibility in 2026: The Foundation of Identity Security
Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Report. This article explains what…
Sep 19, 2026
Read at source →
The Hacker News
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 o…
Sep 19, 2026
Read at source →
The Hacker News
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution. "Orkes…
Sep 19, 2026
Read at source →
SANS Internet Storm Center
HTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th)
In June 2026 the IETF published RFC 10008[1], defining a new HTTP method: "QUERY". The HTTP protocol faced already by changes (HTTP/2, HTTP/3) but it&#x27s the first new standard HTTP verb since "PATCH" in 2010!
Sep 19, 2026
Read at source →
SANS Internet Storm Center
ISC Stormcast For Friday, September 18th, 2026 https://isc.sans.edu/podcastdetail/10100, (Fri, Sep 18th)
Sep 18, 2026
Read at source →

Headlines and snippets © their respective publishers; links go directly to the original sources.

IoT · The overlooked threat surface

IoT on yachts: what most owners miss

Yachts pack more network-connected gadgets than a small office — cameras, AV controllers, smart locks, sensors, infotainment. Most of it ships with weak defaults and never gets patched. Here are the three archetypes we keep seeing in incident reports.

01 Cameras · DVRs
The camera you forgot to patch
IP cameras (Hikvision, Dahua, Axis), smart doorbells, and baby monitors aboard frequently ship with hardcoded creds, open telnet, or unpatched RTSP stacks. One compromised camera = a foothold on the yacht LAN, often with privileged network access for "remote viewing."
Watch for: default passwords, firmware >2 yr old, port 23 open on the guest VLAN
Train crew on device hygiene →
02 AV · Control
Crestron, Lutron, Control4, Savant
AV/lighting/climate controllers expose web admin panels and REST APIs that historically ship with weak auth. They share the same LAN as crew laptops and bridge systems, so a compromise gets full lateral access. Patch cadence is usually "never" without a dedicated integrator.
Watch for: control panels reachable from the guest network, no MFA on admin UIs, vendor remote-access tunnels left enabled
Train crew on segmentation →
03 Guest gear
The "smart" bits guests bring aboard
Chromecasts, Sonos, AirPlay receivers, Bluetooth speakers, smart TVs. Every one is an unmanaged endpoint that broadcasts on the network and can bridge guest devices into the yacht's primary VLAN if segmentation is loose. They're also notorious for shipping with mDNS/UPnP scanning enabled.
Watch for: charter guests plugging anything into wired ports, "easier" flat networks, no MAC allowlist on the crew VLAN
Train crew on guest policy →

Why this matters at sea

Most of these attacks start with a person, not a firewall

Phishing, hostile marina Wi-Fi, guest data slip-ups — the techniques behind the headlines are the same ones that target crew inboxes every day.

Enroll your yacht

Ready to harden your crew's
cyber posture?

Contact us +1.754.600.8735